The Security Architect is a critical leadership role ensuring that our technology, cloud platform, and global operations are secured by design, comply with rigorous global standards, and are guided by a robust security program.
Security Architecture & Strategy Define and maintain CloudPay's security architecture vision, principles, standards, and roadmaps. Ensure security architecture aligns with business objectives, regulatory expectations, and risk appetite. Design secure, scalable patterns for APIs, data platforms, AI workloads, and cloud native services. Provide authoritative security architecture guidance across engineering, platform, and data teams.
Identity & Access Management (IAM) Own the security architecture for workforce and customer identity platforms. Drive adoption of zero trust principles, strong authentication, least privilege access, and secure identity lifecycle management. Provide architectural oversight for single sign on, federation, privileged access management, and conditional access controls. Define and assess future operating models to ensure robust lifecycle management for Identity & Access management exists for CloudPay globally. Collaborate closely with Identity Partners to ensure design and technologies align to CloudPay's 3 A's strategy which includes Automation, API's and AI.
Cloud Security (AWS & Azure) Lead security architecture across AWS and Azure, including identity, networking, encryption, monitoring, and workload protection. Define security guardrails and reference designs using cloud native services and infrastructure as code. Support secure migration, modernization, and continuous improvement of cloud platforms. Ensure continues best practice security principles are applied to cloud platforms deployed by CloudPay and ensure any remediation activities are prioritized by adopting a risk based approach.
AI & Emerging Technology Security Design and review security controls for AI/ML systems, including training data protection, model integrity, access control, and inference security working in conjunction with compliance, security and data privacy teams to ensure controls are appropriate and effective to ensure customer, employee and commercially sensitive data has confidentiality, integrity and availability maintained. Assess and advise on risks associated with generative AI, third party AI platforms, and internal AI use cases. Support responsible, ethical, and compliant adoption of AI technologies from a security and risk perspective.
Architecture Governance & Assurance Chair the Security Architecture Review Board (SARB), ensuring consistent, transparent, and risk informed architectural decision making. Review and approve security relevant architectural designs, exceptions, and risk trade offs. Ensure architecture decisions are documented, traceable, and aligned to enterprise standards. Ensure all platforms, infrastructure, architectures and models are documented and regularly maintained.
Responsible AI & Ethics Leadership Deputize for the Chief Security & Risk Officer and Director of Compliance at the Responsible AI & Ethics Committee. Provide expert security and risk input into AI governance, ethical assessments, and AI assurance decisions. Contribute to policies, controls, and oversight mechanisms for responsible AI use.
Risk, Compliance & Assurance Ensure security designs support compliance with applicable regulations and standards (e.g. ISO 27001, SOC 2, GDPR). Lead threat modeling, security design reviews, and material risk assessments. Support audit, certification, and regulatory activities through well evidenced architecture and governance artefacts.
Stakeholder Engagement & Leadership Act as a trusted advisor to senior engineering leaders, product teams, and executive stakeholders. Influence outcomes through strong communication, pragmatism, and technical authority. Mentor security engineers and architects and promote security by design across the organisation. Act as the Subject Matter Expert (SME), partnering with Enterprise Risk Management, Legal, Internal Audit, Product, and Engineering teams to ensure security requirements are understood and met across the business.
Identity & Access Management Deep experience in IAM architecture for both workforce and customer identities. Strong understanding of modern authentication, authorization, and access governance. Practical application of zero trust and identity centric security models.
Cloud Platforms Advanced knowledge of AWS and Azure security architectures and native security services. Experience designing secure cloud networking, segmentation, encryption, and monitoring. Familiarity with containerized, serverless, and platform as a service security patterns.
AI & Data Security Knowledge of security risks across AI/ML lifecycles, including data ingestion, training, and inference. Experience evaluating AI related threats such as data leakage, prompt injection, and model abuse. Understanding of AI governance and assurance concepts from a security perspective.
Secure Engineering & DevSecOps Experience embedding security into SDLC, CI/CD pipelines, and infrastructure as code. Strong threat modeling, security design review, and architecture documentation skills.
Communication & Architecture Leadership Ability to communicate complex technical concepts clearly to both technical and non technical audiences. Confident written and verbal communication suitable for executive, risk, and governance forums.
CloudPay is committed to being an equal opportunities employer.